<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-68979</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T18:29:16+09:00</news:publication_date>
      <news:title>CVE-2026-68979 Apache NiFi パラメータコンテキスト更新が参照コンポーネントの認可を検査しない（NVD 9.8 / Apache 判定は Medium）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-14537</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-24T18:29:16+09:00</news:publication_date>
      <news:title>CVE-2026-14537 Google mcp-toolbox のレガシー HTTP API 経由で scopeRequired の認可を回避できる（未認証・v1.5.0 で修正）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-17543</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-23T18:13:46+09:00</news:publication_date>
      <news:title>CVE-2026-17543 PHP の PostgreSQL 拡張にバックスラッシュのエスケープ漏れによる SQL インジェクション</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-17544</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-23T18:13:46+09:00</news:publication_date>
      <news:title>CVE-2026-17544 PHP の BCMath 拡張 bccomp() に領域外書き込み（スタックとヒープを破壊）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-72529</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-22T20:07:50+09:00</news:publication_date>
      <news:title>CVE-2026-72529 TrueConf Server の 4307/TCP に認証が無い（未文書の関数呼び出しで任意スクリプト実行・KEV 収載）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-72530</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-22T19:30:08+09:00</news:publication_date>
      <news:title>CVE-2026-72530 TrueConf Server の 4307/TCP でコードインジェクション（隔離環境を脱してホストで任意コード実行・KEV 収載）</news:title>
    </news:news>
  </url>
  <url>
    <loc>https://cve.autoarticles.net/cve/CVE-2026-73570</loc>
    <news:news>
      <news:publication>
        <news:name>脆弱性対応ウォッチ</news:name>
        <news:language>ja</news:language>
      </news:publication>
      <news:publication_date>2026-08-22T19:30:08+09:00</news:publication_date>
      <news:title>CVE-2026-73570 Zimbra Collaboration の SNMP 通知処理に OS コマンドインジェクション（KEV 収載・是正期限 2026-08-24）</news:title>
    </news:news>
  </url>
</urlset>